GDPR & UK Data Protection Standards
-
1. Identification of the Data Controller
Sovereign Media Group Ltd, operating from Suite 93, 101 Greenfield Road, London, E1 1EJ, United Kingdom, acts as the independent data controller for sovereignmediaagency.com under Director Stacey Kingsley.
-
2. Regulatory Compliance & Applicable Frameworks
We process all personal data strictly in conformity with Regulation (EU) 2016/679 (GDPR), the UK Data Protection Act 2018, PECR, and the Polish Personal Data Protection Act of 10 May 2018.
-
3. Categories of Personal Data Collected
Data collected is limited to name, email address, optional phone number, requested dates of stay, and technical browser telemetry.
-
4. Lawful Grounds for Processing (Article 6 GDPR)
Processing relies on consent (Art. 6(1)(a)), legitimate interests for cybersecurity (Art. 6(1)(f)), and compliance with legal obligations (Art. 6(1)(c)).
-
5. Purposes of Data Processing and Utilization
Your information is utilized to respond to communications, forward booking inquiries to official hotel desks upon request, and optimize website stability.
-
6. Data Retention Schedules and Deletion Protocols
Inquiry submissions are retained for a maximum of 12 months before deletion. Server access logs are securely purged within 30 days.
-
7. Technical Security Measures and Safeguards
We deploy 256-bit TLS/HTTPS encryption in transit, strict access control mechanisms, and isolated server environments to protect data.
-
8. International Data Transfers
Transfers between the UK and EEA rely on adequacy decisions. Transfers to third countries comply with EU Standard Contractual Clauses (SCCs).
-
9. Third-Party Disclosure and Service Providers
We do not sell or monetize personal data. Disclosures are limited to secure hosting infrastructure and verified hotel desks upon user request.
-
10. Comprehensive Data Subject Rights
You hold the right to access, rectify, erase, restrict, port, and object to processing by emailing qusifone146@gmail.com.
-
11. Automated Decision-Making and Profiling Exclusions
We do not engage in automated decision-making processes or automated profiling.
-
12. Protection of Minors & 18+ Casino Policy
We do not knowingly collect data from individuals under 18. Casino gaming on the premises is strictly restricted to adults aged 18 and older under Polish law.
-
13. Policy Amendments and Supervisory Authorities
You have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) or the Polish Data Protection Office (UODO).